InterviewSolution
| 1. |
Solve : Trojans wont let me go to anti-malware web addresses!!? |
|
Answer» Hello y'all, newb here with first post.
--> FIL\\\?\C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-00000005.dll [DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.JW back-door program C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-0000000A.sys
--> FIL\\\?\C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\TEMP\AVSCAN-20090531-094504-7F1BF2A5\AVSCAN-0000000A.sys [DETECTION] Is the TR/Rootkit.Gen Trojan The repair notes were written to the file 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\AVSCAN-20090531-094623-9003C82F.avp'. c:\windows\system32\tdsscfub.dll [INFO] The file is not visible. [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was deleted! c:\windows\system32\drivers\tdsspaxt.sys [DETECTION] [NOTE] The file was deleted! c:\windows\system32\tdssfpmp.dll [INFO] The file is not visible. c:\windows\system32\tdssnrsr.dll [INFO] The file is not visible. [DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.adb back-door program [INFO] No SpecVir entry was found! c:\windows\system32\tdssoeqh.dll [DETECTION] [INFO] No SpecVir entry was found! c:\windows\system32\tdssosvn.dat [INFO] The file is not visible. c:\windows\system32\tdssrhym.log [INFO] The file is not visible. c:\windows\system32\tdssriqp.dll [INFO] The file is not visible. [DETECTION] Contains a recognition pattern of the (harmful) BDS/TDSS.acs back-door program [INFO] No SpecVir entry was found! c:\windows\system32\tdsstkdv.log [INFO] The file is not visible. c:\documents and settings\chaka\local settings\temp\tdss8d6f.tmp [INFO] The file is not visible (shell). [DETECTION] Is the TR/Patched.CL Trojan [INFO] No SpecVir entry was found! End of the scan: Sunday, May 31, 2009 09:46 Used time: 01:23 Minute(s) The scan has been done completely. 0 Scanning directories 10 Files were scanned 6 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 2 files were deleted 0 files were repaired 0 files were moved to quarantine 0 files were renamed 0 Files cannot be scanned 4 Files not concerned 0 Archives were scanned 0 Warnings 2 Notes 51894 Objects were scanned with rootkit scan 15 Hidden objects were found The issue I am having is ANY web browser I use (Firefox 3.0.10, IE 8, or Opera) will not let me connect to ANY anti malware sites. I get a 'could not connect to.....' prompt. I had AVG, but trojan would not let me update definitions. I have MaxPC cd with Superantispyware and MALWAREBYTES, but cannot install, says files are corrupt (only these 2 of course!). ALL Google inquires are redirected to malware sites or Apartmentfinder on all browsers. I deleted and/or Quarantine through the anti virus but they come back upon reboot. I suspect AV is compromisedjavascript:replaceText('%20>',%20document.forms.postmodify.message); I am at wits end and out of options EXCEPT format, but do not have XP cd so this is my only hope! [attachment deleted by admin]update Was able to run hijack this Logfile of HijackThis v1.97.7 Scan saved at 12:23:20 PM, on 5/31/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe e:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe E:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe F:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe E:\apps\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.6.14.dll O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O11 - Options group: [INTERNATIONAL] International O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/ActiveX/VMRCActiveXClient1.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - O17 - HKLM\System\CCS\Services\Tcpip\..\{C9F18C6A-744A-4A9B-A644-74ADAA6E8121}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CCS\Services\Tcpip\..\{EF2FA76B-F1B8-49B8-B1D0-A18671B3A868}: NameServer = 208.67.222.222,208.67.220.220 Was able to download malwarebytes but freezes on install. adaware and spybot will not let mu update. |
|